Skip to content

fix(check_dataset_allowlist): import env_config in both invocation co… #41

fix(check_dataset_allowlist): import env_config in both invocation co…

fix(check_dataset_allowlist): import env_config in both invocation co… #41

Workflow file for this run

name: Hands Tests
# PyAutoHands's own unit suite — the executor's self-test. Until this existed,
# PyAutoHands PRs carried ZERO check runs: `python_matrix.yml` is a weekly cron
# over the five *libraries'* suites, `navigator_check.yml` is `workflow_call`
# only (invoked by the workspaces), and `release.yml`'s pytest step runs inside
# `${{ matrix.project.path }}` — a matrix of the five libraries, with
# PyAutoHands checked out beside them only as a helper. So the ~300 tests
# covering build_util (script/notebook execution, per-script timeouts,
# clean-skip exits), env_config (profile discovery, per-script env, JAX
# marking, workspace precedence), result_collector, check_navigator,
# clone_seed, the release/Slack notes and the workflow parsers ran in no CI at
# all, and a Hands PR's only gate was whatever the authoring session ran
# locally.
#
# That gap had already bitten: b038fdc promoted Python 3.14 to a required
# matrix leg and retired the experimental_python_314 job, but left
# test_python_matrix_workflow.py asserting the pre-promotion contract. The
# guard test sat failing with nothing to report it.
#
# pytest plus ONE drift leg. It must not invoke `autohands generate` / `run_all`
# / `pre_build` against live workspaces, and must not reach the network — those
# need sibling workspace checkouts and belong to release.yml and the scheduled
# drivers, not to a PR gate. What runs here is stdlib plus four small packages,
# so it stays fast (~6s) and flake-free. The one non-pytest step is the
# tenant-firewall gate (PyAutoMind#198): every firewall finding to date merged
# through a green PR because no PR CI ran the check, so the leg a Hands PR can
# cause is verified here, in the PR that authors it. `--only` keeps Mind-side
# legs (map blocks, registries) from reddening Hands PRs on drift Hands cannot
# cause; organs not checked out (Brain, Heart) are skipped by the check itself,
# so this gates exactly Hands. PyAutoMind is checked out as a sibling purely to
# supply the checker and the body map — it is pinned to main, so this gate
# measures Hands against the CURRENT organism identity, the same pairing a local
# workspace has. Both repos are public, so the default GITHUB_TOKEN suffices.
#
# Dependencies are named explicitly rather than `-r requirements.txt`, which
# would drag in jupyterlab + ipykernel and turn a 6s gate into a slow one:
# pytest the runner
# PyYAML env_config / validate_env_profiles / the workflow parsers
# ipynb-py-convert a CLI binary build_util shells out to (not an import)
# Pillow generate_markdown's PNG optimisation path
# FOUR tests self-skip here, and they are two different kinds:
# - 3 on absent nbformat/jupyter (test_run_notebook_cwd,
# test_notebook_skip_exit) — intentional, that is the notebook-execution
# path release.yml covers.
# - 1 because this checkout has no sibling workspaces:
# test_workspace_config_precedence.test_actual_workspace_files_exist walks
# `repo_root.parent / <workspace>` asserting each of the six workspaces owns
# its config/build/{no_run,profile_smoke,visualise_notebooks}.yaml, and
# skips at the first one absent. In a full local workspace it asserts all
# six; here it asserts nothing.
# That second one is a real hole in this gate, accepted deliberately: closing it
# means six extra checkouts for a repo-layout invariant, which would couple a 6s
# gate to six other repos. It is a local/developer check, not a PR check. Local
# baseline is therefore 301 passed / 3 skipped; CI is 300 passed / 4 skipped.
# One run per commit: PR events carry the CI; pushes only build main.
# Superseded runs are cancelled on PR refs only — a cancelled main run would
# read as red CI (cancelled is in Heart's FAILURE_CONCLUSIONS).
on:
push:
branches: [main]
pull_request:
concurrency:
group: hands-tests-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
permissions:
contents: read
jobs:
pytest:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
# Tracks the required set python_matrix.yml declares supported (3.14
# promoted in b038fdc). test_python_matrix_workflow.py asserts the two
# stay equal, so this list cannot silently fall behind that policy.
python-version: ["3.12", "3.13", "3.14"]
steps:
- name: Checkout PyAutoHands
uses: actions/checkout@v4
with:
path: PyAutoHands
# The checker + body map the firewall gate runs. Pinned to main: this
# gate measures Hands against the CURRENT organism identity.
- name: Checkout PyAutoMind (the firewall checker + body map)
uses: actions/checkout@v4
with:
repository: PyAutoLabs/PyAutoMind
path: PyAutoMind
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python-version }}
cache: pip
- name: Install (the whole dependency set — see header)
run: pip install pytest PyYAML ipynb-py-convert Pillow
- name: Run tests
working-directory: PyAutoHands
run: pytest tests/ -q
- name: Tenant firewall (instance facts stay in declared config surfaces)
run: >
python3 PyAutoMind/scripts/repos_sync.py --check
--only "tenant firewall (organ code)"
--root "$GITHUB_WORKSPACE"